Showing posts with label Technical. Show all posts
Showing posts with label Technical. Show all posts

Monday, November 19, 2007

Reconstructing fingerprint images from templates

This is for everyone who thinks fingerprints cannot be reverse engineered from biometric systems, and especially for Jim Knight MP, the Labour Minister for Schools and Learners, who offered up the below incorrect information in a parliamentary debate in July this year with Greg Mulholland MP:

"Secondly, as I stated earlier, it is not possible to recreate a fingerprint using the numbers that are stored. The algorithm generates a unique number, producing no information of any use to identity thieves. I shall quote from a statement from the Information Commissioner’s Office—a thoroughly independent source—that says in the third paragraph:

“Full fingerprint images are not stored and cannot be generated (‘reverse engineered’) from the template.”

I hope that that is clear to all those listening, because it is an important reassurance on the points that the hon. Gentleman has made." ...absolutely crystal Jim.


1. Original fingerprint scan
2. Stored fingerprint template

3. Print reconstructed from template
Arun Ross, Member, IEEE, Jidnya Shah, and Anil K. Jain, Fellow, IEEE
April 2007
(as shown on the Leave Them Kids Alone site)

Tuesday, July 31, 2007

Reverse-engineering digital fingerprints

One important point, that has been reiterated time and time again by biometric vendors, Jim Knight and the ICO, is that the biometric systems in schools cannot reverse-engineer a fingerprint.

This does not seem to be the case according to Kim Cameron's recent weblog, Architect of Identity and Access in the Connected Systems Division at Microsoft, entitled "Paper argues biometric templates can be reversed". It shows that reverse-engineering a digital fingerprint may just be possible. He cites this paper "Can images be generated from biometric templates" by Andy Adler, University of Ottawa, 2003.

Also see these Research discussions at West Virginia University from 2005 "We show that minutiae information can reveal substantial details such as the orientation field and the class of the associated fingerprint that can potentially be used to reconstruct the original fingerprint image."

Both of these papers are not too recent and since then one would presume that the technologies in this field have advanced.

However, even thought the possible reconstruction of a fingerprint seems relevant to the argument of biometric technology in schools, ownership and possible 'loss' of ones digital fingerprint is still very relevant... who has access to it, the systems it is on, how it can be used (or abused). These are the points that should be seriously considered by children (and parents) as they unwittingly give up their biometric data for systems in schools which are non essential for purchasing food or accessing library books.

Tuesday, April 24, 2007

Consent and Security

Futurelab published a well written article (Now archived here) in December last year, in their bi-annual magazine 'Vision', about surveillance in schools concentrating mainly on biometric systems. It clearly defines the two issues that concern parents and security experts:

First, the taking and storage of the biometric data itself. Second, the lack of consultation beforehand. The second of these issues is as contentious as the first, even though the DfES said in September 2006 that, in its view, schools do not need to ask permission.

The fingerprint module in Junior Librarian, for example, is bought in from a third-party company that supplies its technology to a range of other vendors for many other uses. Isn't it possible that today's database of children's fingerprints, sometime in the future, could unlock some completely different application and set of data?

This from Terence Boult on Bruce Schneier's blog from 2005.

"This obscure phrasing ["The data cannot be used to reconstruct the fingerprint"] is common among biometric vendors... to make people feel its more private and/or safer. Minutiae-based templates can be easily reused by the government, and there is an official interchange standard (M1) to help ensure systems can share and inter-operate... to ensure one company's templates work well in other peoples' matching."

One would presume that this side of biometric technology has matured even since then.

On issues of security, with no awareness at any level of how many regular schools computers currently store children's biometric data - how then do we know when their data gets stolen or compromised? For certain when schools get broken into it's not pens and paper that get stolen.

The issue of children's consent remains a contentious issue, especially when they are in a compliant environment. Systems in schools should be on an "opt in" basis, this would force a school to explain the technology thoroughly to parents and also give both parents and pupils time for research themselves. Without informed consent we stand a very real risk of teaching the next generation to be casual with their personal biometric data.

Futurelab, who received major start-up funding from the Department for Education and Skills, DfES, has this last comment on the subject:

Maybe the time has come for a debate on this issue so that we can all fully understand both the positive and negative aspects of using surveillance technology in schools - and then, at least, we can all make an informed choice as to whether or not to sign up.

Monday, February 19, 2007

It's not a fingerprint but a number...

Too often the argument in defence of fingerprinting children in school is that "the system doesn't store a fingerprint, but a number". So that's okay then...

This is quoted 'ad lib' to the press by schools and bio-companies targeting schools.

What is stored is the digital equivalent of a fingerprint, uniquely identifiable to a particular person/child - otherwise if the biometric technology used in schools couldn't identify a particular child (via their fingerprints) the systems wouldn't work and issue library books, logged meals eaten, track a child's whereabouts, etc, against a child's name.

The police now use very similar systems, in the fact that they too use digital technology to store and compare fingerprints, to the systems used in schools.

The argument "that it's not a fingerprint that is stored" is irrelevant as it is fingerprint data that stored on a school database which is relatively insecure in comparison to the importance placed on storing biometrics on databases that large IT companies have.

As Andy Clymer states in a paper he has written: "No system can guaranteed the security of information against future technology. Attempting to protect life time relevant information is extremely tricky and potentially costly."

On that note, the computers of the future are just about here. Welcome to quantum computing which "...has IT security firms and spooks afraid their current encryption technologies will be rendered obselete when a quantum computer with hundreds of qubits arrives.."

Estimated time of arrival - 2008

Sunday, February 04, 2007

How biometric fingerprint scanners work

After yesterday's post I thought it might be good to look at how the technology works for those of you that are interested.

I have had a few 'comments' on my blog highlighting me to the fact it is not an actual fingerprint that is stored but an algorithm, which I was well aware of anyway, but for those of you who are as hazy as I was initially, on how biometric data is taken from a fingerprint, please use the below links.

A great website that gives a fairly detailed but easily understandable view on most types of biometrics is here.

This website details here on the characteristics of fingerprints and this page deals with how points on the fingerprint are converted into an algorithm number string.

When I had contact with Micro Librarian Systems (MLS) that supplied my children's primary school with the biometric fingerprint scanner 18 months ago, they sent me this document detailing the technology that they employed - Enterprise Security Architecture for Biometric User Authentication Systems developed by Digital Persona.

Could it be argued that the points on a fingerprint stored in an algorithm can determine race and ethnicity? - I don't know...

Are the images of a children's fingerprint removed from a school computor when they are initially scanned? - Truely deleting data or temporary files from a hard drive does not merely involve pressing "delete". Temporary files may be stored for a time scale also...

Research needs to be done exploring these (and other) issues relating to children and biometric technology.

Children as young as 3 years old are having their biometric data taken and stored on school/nursery databases here in the UK and, as with all techonogies, there is the remote possibly that their (biometric) data could be compromised in decades to come.

We need to make informed decisions now about how we as a society proceed with children and biometric technology.